Vulnerability CVE-2004-2764


Published: 2009-06-02   Modified: 2012-02-12

Description:
Sun SDK and Java Runtime Environment (JRE) 1.4.2 through 1.4.2_04, 1.4.1 through 1.4.1_07, and 1.4.0 through 1.4.0_04 allows untrusted applets and unprivileged servlets to gain privileges and read data from other applets via unspecified vectors related to classes in the XSLT processor, aka "XML sniffing."

See advisories in our WLB2 database:
Topic
Author
Date
High
Java XSLT security advisory addendum
Marc Schoenefeld
03.06.2009

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
SUN -> JRE 
SUN -> SDK 

 References:
http://archive.cert.uni-stuttgart.de/uniras/2004/08/msg00007.html
http://groups.google.com/group/comp.security.unix/tree/browse_frm/month/2004-10/fe63f1daa9689d50?rnum=161&_done=%2Fgroup%2Fcomp.security.unix%2Fbrowse_frm%2Fmonth%2F2004-10%3Ffwc%3D1%26#doc_29036353582c690d
http://securitytracker.com/id?1011661
http://www.securityfocus.com/archive/1/371208
http://www.securityfocus.com/bid/10844
https://exchange.xforce.ibmcloud.com/vulnerabilities/16864

Copyright 2024, cxsecurity.com

 

Back to Top